www.com-about.com

WHOISGUARD, INC.  (Proxy Registrant)

Domain Information

The domain www.com-about.com is registered by proxy through ENOM, INC. and was originally registered in February of 2006. This domain has been known to host and distribute adware as well as other potentially unwanted software. The hosted servers are located in Paris, Ile-De-France within France which resides on the Asia Pacific Network Information Centre network.
Registrar:
ENOM, INC.

Server location:
Ile-De-France, France (FR)

Create date:
Tuesday, February 7, 2006

Expires date:
Tuesday, February 7, 2017

Updated date:
Saturday, January 9, 2016

Root domain:

Scanner detections:
Detections  (78% detected)

Scan engine
Details
Detections

Reason Heuristics
PUP.DownloadAtoZ.Bundler.Meta (M), Adware.Mutabaha.DB (M), PUP.InstallCore.AC.Installer (M)
71.43%

Dr.Web
Adware.Mutabaha.301
71.43%

ESET NOD32
Win32/Downloader.AtoZ.A potentially unsafe application
57.14%

Trend Micro House Call
Suspicious_GEN.F47V1225
14.29%

AhnLab V3 Security
Trojan/Win32.HDC
14.29%

McAfee
Artemis!79004B97E5DF
14.29%

Norman
DLoader.ATMMQ
14.29%

ViRobot
Trojan.Win32.A.Gena.3173376.B[h]
14.29%

Emsisoft Anti-Malware
Application.AdLoad
14.29%

NANO AntiVirus
Riskware.Win32.Mutabaha.eaoiix
14.29%

The domain www.com-about.com has been seen to resolve to the following 3 IP addresses.

163-172-16-30.rev.poneytelecom.eu
March 31, 2016

April 2, 2015

April 2, 2015

File downloads found at URLs served by www.com-about.com.

0 / 68

9 / 68      (PUP)
http://www.com-about.com/download/.../clone-genius.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)
http://www.com-about.com/download/.../nero-8.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)
http://www.com-about.com/download/.../kb-speeded-up-tool.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)
http://www.com-about.com/download/.../resolume.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)
http://www.com-about.com/download/.../pmd.exe  (windows-media-player-12_117534.exe)

3 / 68      (PUP)

9 / 68      (PUP)

9 / 68      (PUP)
http://www.com-about.com/download/.../norton-ghost-10-0.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)
http://www.com-about.com/download/.../ifs-viewer.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)
http://www.com-about.com/download/.../avisubdetector.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)

9 / 68      (PUP)

9 / 68      (PUP)

9 / 68      (PUP)

9 / 68      (PUP)
http://www.com-about.com/download/.../ifscl.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)

9 / 68      (PUP)

9 / 68      (PUP)
http://www.com-about.com/download/.../savemedia.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)

9 / 68      (PUP)

9 / 68      (PUP)
http://www.com-about.com/download/.../shoot-em-up-kit.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)
http://www.com-about.com/download/.../quikgrid.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)
http://www.com-about.com/download/.../reghunter.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)

9 / 68      (PUP)
http://www.com-about.com/download/.../javafoil.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)
http://www.com-about.com/download/.../runasdate.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)
http://www.com-about.com/download/.../rxlist-offline.exe  (windows-media-player-12_117534.exe)

9 / 68      (PUP)
http://www.com-about.com/download/.../loopbe.exe  (windows-media-player-12_117534.exe)

 
Latest 30 of 116 download URLs

The following 2 files have been seen to comunicate with www.com-about.com in live environments.

URL:
http://www.com-about.com/

Google Analytics:
UA-11313961

Title:
“Free Software Download for Windows: freeware, shareware, open source software”

Description:
“Free software downloads for Windows 98, 2000, NT, XP, Vista & Windows 7.”

SSL certificate subject:
CN=sni32986.cloudflaressl.com, OU=PositiveSSL Multi-Domain, OU=Domain Control Validated

SSL certificate issuer:
CN=COMODO ECC Domain Validation Secure Server CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Web server:
nginx (PHP/5.3.3)